Privacy policy
Vintage Handbag Identifier
Last updated: 9 August 2026
Vintage Handbag Identifier is built by Josh Waller, trading as Kovus, in Perth, Western Australia. The app does not ask for your name, email address or phone number, and it does not use advertising identifiers or ad networks.
Website release waitlist
The release waitlist is closed. If you joined before it closed, the website may retain the email address you supplied together with the form location, country and signup time in Cloudflare KV. Those records are not used for ongoing marketing. Email josh@kovus.dev to request deletion.
Creed scans
Creed photos are sent over an encrypted connection to our Supabase Edge Function and read by Google Gemini. Kovus does not write creed photo bytes to storage or retain a copy after processing. Google handles the request under its own Gemini API terms.
If your iPhone is offline, or the reading service cannot be reached, the stamp is read on your iPhone using on-device text recognition instead. Either way, the app uses the recognised style and serial information to search its bundled catalogue. Photos you import from your library are only ever touched as a temporary copy, and temporary camera copies are deleted after processing.
Whole-bag photo identification
If you choose whole-bag identification, up to four photos are sent over an encrypted connection to our Supabase Edge Function and processed by either Google Gemini or Anthropic Claude. Before you consent, the app names both possible providers; it does not identify which one the service will select for that request. The photos are used only to compare visible bag details with catalogue facts. Kovus does not save the photo files, and the server clears their in-memory bytes after the request finishes.
Google and Anthropic handle API inputs and outputs under their own contractual retention terms. If a comparison cannot be sent while your phone is offline, the app may keep one pending retry, including its selected photos, in private local storage until you retry or discard it.
Anonymous service records
The app creates a random anonymous Supabase account so the service can manage paid entitlements and prevent abuse without asking you to sign in. For a creed read, Kovus keeps the anonymous account identifier, the request time and the processing cost, which are the records that enforce burst limits and the daily spending ceiling. A creed read does not spend a credit, and no model name is kept for it. For a whole-bag identification, Kovus keeps those same records plus the model name and the credit usage record. With the app’s default no-retention consent setting, Kovus does not store the bag photos, creed text, extracted attributes or candidate results.
Information kept on your iPhone
- Your saved collection, notes, nicknames and any collection photos you choose to keep.
- Your recent identification history and app preferences.
- Your onboarding and collector-profile answers.
- A pending whole-bag request if you explicitly keep it for an offline retry.
You can remove saved pieces and their photos inside the app. Deleting the app removes its local data, subject to Apple’s device backup behaviour.
Product analytics and crash reports
Sharing anonymous diagnostics is off by default. If you enable it in the app’s privacy controls, Kovus uses PostHog for basic product events such as onboarding completion, scan starts, result reveals and paywall views, and may use Sentry for crash and error reports. Session replay is disabled. Default personal information is disabled, user identity and breadcrumbs are removed, and photos and creed text are never attached to analytics or crash events. These services may still process technical information such as a random installation identifier, app version, device type, operating system and network request metadata. You can turn diagnostics off again at any time.
Purchases
Apple processes payments. RevenueCat manages subscription status using a random app user identifier and purchase information such as product identifiers, transaction status and receipt data. Kovus does not receive your card or bank details.
Service providers
- Supabase hosts anonymous authentication, entitlement controls and catalogue services.
- Google Gemini reads creed photos when your iPhone is online.
- Google or Anthropic may process whole-bag photos for catalogue matching.
- PostHog and Sentry provide product analytics and crash diagnostics only when you enable them.
- RevenueCat and Apple manage purchases and subscription status.
- Cloudflare hosts this policy and processes normal web request metadata.
Retention, deletion and your choices
In the app, open More and choose Delete my data to permanently remove your anonymous service records, remaining identification credits and private collection stored on that phone. Apple keeps purchase records under its own policy, and eligible purchases may be restored through Apple.
Deleting app data does not cancel an App Store subscription.Cancel that in Apple’s subscription settings or it keeps renewing. Anonymous operational records otherwise remain only while needed to enforce limits, account for credits, prevent abuse, investigate failures and meet legal obligations. Apple, RevenueCat, Supabase, Google, Anthropic, PostHog and Sentry apply their own contractual retention periods to data they process for Kovus.
You can deny camera access in iOS Settings and still use catalogue features that do not require it. The in-app control is the primary deletion route. For access, correction or deletion help, email josh@kovus.dev. We may need an anonymous support identifier or transaction reference to locate the correct record without collecting your identity.
Children
Vintage Handbag Identifier is not directed to children under 13 and does not knowingly collect personal information from children.
Changes and contact
Material changes will be published at this address with a revised date. Privacy questions can be sent to josh@kovus.dev. You may also contact the Office of the Australian Information Commissioner at oaic.gov.au.
Also see App support.